FG-IR-26-162: UI DoS attack
Published Aug 12, 2026
·Updated
An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests.
Affected Software
3 affected componentsFixes available
Fortinet FortiOS>=7.6.0<=7.6.6
Fortinet FortiOS>=7.4
Fortinet FortiOS>=7.2
Event History
Aug 12, 2026
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-26-162?
The severity of FG-IR-26-162 is medium with a score of 5.
2
How do I fix FG-IR-26-162?
To mitigate FG-IR-26-162, implement rate limiting or traffic throttling on the web interface.
3
What type of attack does FG-IR-26-162 pertain to?
FG-IR-26-162 pertains to a UI Denial of Service (DoS) attack via slow HTTP requests.
4
Who is affected by FG-IR-26-162?
FG-IR-26-162 affects users of Fortinet FortiOS due to vulnerabilities in the web interface.
5
What can an attacker achieve with FG-IR-26-162?
An attacker can perform a slow HTTP DoS attack, overwhelming the web interface and causing service disruption.